Encryption and authentication method and device for Linux virtual machine

By establishing three security authentication systems in Linux virtual machines, the problem of single access authentication methods of virtual machines is solved, and high security authentication and the uniqueness and non-replicability of virtual machines are achieved.

CN120068053APending Publication Date: 2025-05-30BEIJING WUYI JIAYU TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411950220.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In the prior art, the authentication method of virtual machine access is relatively single, and there are unsafe factors, which makes it difficult to effectively solve the problems of password leakage, complex key management and high time synchronization requirements.

Method used

By establishing three security authentication systems in Linux virtual machines, including TPM authentication, certificate verification and ssh password authentication, we ensure that the virtual machine performs multi-level security authentication during booting, access control and certificate verification.

Benefits of technology

It realizes high security authentication of virtual machines to prevent illegal access and data leakage, and ensures the uniqueness of virtual machines and the non-replicability of business code.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068053A_ABST
    Figure CN120068053A_ABST
Patent Text Reader

Abstract

The invention provides an encryption and authentication method and device for a Linux virtual machine. The encryption and authentication method comprises the following steps: starting up the virtual machine after the virtual machine is wholly copied; acquiring TPM (Trusted Platform Module) authentication information, authenticating the TPM authentication information, if the authentication is successful, determining that the virtual machine is successfully copied, and executing a virtual machine startup operation; after the virtual machine is started, waiting for loading of the server; judging whether the IP is allocated or not, and if the IP is allocated, allowing wab access; the certificate information is verified, and if verification is passed, the virtual machine is allowed to be used normally; wherein after the virtual machine is started up and before the virtual machine is allowed to be used normally, security limitation is further carried out on a modified ssh password password, after verification fails, the virtual machine is prevented from being started up after being integrally copied, and then the wab service cannot be started normally. According to the invention, a three-time security authentication system is established, so that the service security and non-replicability are ensured; a self-built safety console is operated and embedded into an operating system in a guiding mode; and the security of the virtual machine and the non-replicability of codes of a unique service system are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of secure communication, and in particular, to a method and device for encrypting and authenticating a Linux virtual machine. Background Art

[0002] With the development of Internet technology, in order to ensure the security of communication, visitors are often authenticated. There are the following several authentication methods in the prior art:

[0003] 1. Password-based offline authentication. In this method, the user needs to enter a password, and the system will verify it by comparing it with the user's password internally. Only after the verification is passed can the user access the system or resources. However, the security of this authentication method is relatively low: the password may be cracked or leaked, and it is vulnerable to brute-force attacks, dictionary attacks, etc.; the password can be copied and misused; at the same time, it is difficult to manage: the password needs to be properly stored, and security problems may occur when the password is forgotten or leaked.

[0004] 2. Key pair-based offline authentication. This authentication method is an authentication method based on the public key encryption system, and uses public and private key pairs for identity authentication. Usually, asymmetric encryption technology is adopted. The private key is retained on the user side, while the public key can be widely distributed. However, the key management of this authentication method is complex: the private key needs to be properly stored and its security needs to be ensured; on some low-power devices, the storage and encryption / decryption calculations of the private key may be restricted; the problem of replication and abuse cannot be solved.

[0005] 3. Time synchronization-based offline authentication. This authentication method usually uses the time-based one-time password (TOTP) technology. TOTP is an authentication method that generates a one-time password based on the current timestamp and a shared key. TOTP does not require a real-time network connection because it depends on time synchronization. However, this authentication method has high requirements for time synchronization: the client and the server need to keep time synchronization to ensure the correct generation of the password; the key management is difficult, and the shared key needs to be properly stored. Once it is leaked, the authentication mechanism will be affected.

[0006] Based on the above authentication methods, the authentication of virtual machine access in the prior art is relatively single and there are security risks. Therefore, providing a new authentication method for virtual machines has become an urgent problem to be solved. Summary of the Invention

[0007] The present invention aims to provide a method and device for encrypting and authenticating a Linux virtual machine that overcome the above problems or at least partially solve the above problems.

[0008] To achieve the above object, the technical solution of the present invention is specifically implemented as follows:

[0009] One aspect of the present invention provides a method for encrypting and authenticating a Linux virtual machine, including:

[0010] After the virtual machine is copied as a whole, it is powered on;

[0011] Obtain the TPM authentication information, authenticate the TPM authentication information. If the authentication is successful, it is determined that the virtual machine copy is successful, and the virtual machine power-on operation is executed;

[0012] After the virtual machine is powered on, wait for the server to load;

[0013] Judge whether the IP is allocated. If the IP has been allocated, allow wab access;

[0014] Verify the certificate information. If the verification passes, allow the virtual machine to be used normally;

[0015] Wherein: after the virtual machine power-on operation and before allowing the virtual machine to be used normally, it further includes:

[0016] Authenticate the modified ssh password. After the verification fails, prevent the operation of powering on the virtual machine after it is copied as a whole.

[0017] Optionally, the obtaining the TPM authentication information and authenticating the TPM authentication information includes:

[0018] Obtain the input TPM encryption key and verify the TPM encryption key.

[0019] Optionally, the authenticating the modified ssh password includes:

[0020] Obtain the modified ssh password, obtain the static key, verify the static key. After the verification passes, execute the modified ssh password operation, and judge the hash of the modified ssh password through the TPM encryption module.

[0021] Optionally, the verifying the certificate information includes:

[0022] Judge whether there is a certificate;

[0023] If there is the certificate, judge whether the certificate is valid through the USB-Key. If it is valid, determine that the verification passes. If it is invalid, prompt to upload a valid certificate;

[0024] If there is no such certificate, prompt to upload a valid certificate.

[0025] Optionally, the method further includes:

[0026] If the IP is not allocated, enter the boot shell to manually allocate the IP and perform the operation to allow wab access.

[0027] Another aspect of the present invention provides an encryption and authentication device for a Linux virtual machine, including:

[0028] A copy module for booting after the virtual machine is copied as a whole;

[0029] A first authentication module for obtaining TPM authentication information and authenticating the TPM authentication information;

[0030] A boot module for determining that the virtual machine copy is successful after the first authentication module authenticates successfully, and performing the virtual machine boot operation;

[0031] An access control module for, after the virtual machine boots and waits for the server to load, determining whether the IP is allocated, and if the IP is allocated, allowing wab access;

[0032] A second authentication module for verifying the certificate information;

[0033] A processing module for allowing the virtual machine to be used normally after the second authentication module verifies successfully;

[0034] A third authentication module for authenticating the modified ssh password before the processing module allows the virtual machine to be used normally after the virtual machine boot operation of the boot module, and preventing the copy module from performing the operation of booting after the virtual machine is copied as a whole if the verification fails.

[0035] Optionally, the first authentication module obtains the TPM authentication information and authenticates the TPM authentication information in the following manner:

[0036] Obtain the input TPM encryption key and verify the TPM encryption key.

[0037] Optionally, the third authentication module authenticates the modified ssh password in the following manner:

[0038] Obtain the modified ssh password, obtain the static key, verify the static key, and perform the modified ssh password operation after the verification passes, and perform a hash judgment on the modified ssh password through the TPM encryption module.

[0039] Optionally, the second authentication module verifies the certificate information in the following manner:

[0040] Determine whether there is a certificate;

[0041] If the certificate exists, it is determined whether the certificate is valid through the USB-Key. If it is valid, the verification is determined to pass; if it is invalid, a prompt is given to upload a valid certificate.

[0042] If the certificate does not exist, a prompt is given to upload a valid certificate.

[0043] Optionally, the access control module is further configured to, if the IP is not assigned, enter the boot Shell, manually assign the IP, and perform the operation of accessing wab.

[0044] It can be seen that through the encryption and authentication method and device for a Linux virtual machine provided by the present invention, a three-level security authentication system is established to ensure service security and non-replicability from the perspectives of software and hardware and service authentication; a security console can be built and operated and embedded in the operating system in a boot mode; the security, uniqueness, and non-replicability of the service system code in the case of supplying virtual machines through the vmware virtual machine are guaranteed. Description of the Drawings

[0045] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0046] Figure 1 It is a flowchart of the encryption and authentication method for a Linux virtual machine provided by an embodiment of the present invention;

[0047] Figure 2 It is a specific flowchart of an encryption and authentication method for a Linux virtual machine provided by an embodiment of the present invention;

[0048] Figure 3 It is a schematic structural diagram of the encryption and authentication device for a Linux virtual machine provided by an embodiment of the present invention. Detailed Embodiments

[0049] The exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art.

[0050] The core of the present invention lies in: by encrypting the virtual machine disk and the underlying storage, it can effectively prevent the leakage and tampering of data on the storage medium. Even if an attacker obtains access to the physical storage device, they cannot decrypt the sensitive data of the virtual machine, ensuring the non-replicability of the data. In addition, disk encryption ensures that even if the data is illegally copied or transferred, it cannot be effectively accessed. The unique authentication mechanism ensures that only authorized users can access the encrypted data through authentication, and the authentication process usually relies on unique authentication credentials, making the authentication information impossible to be copied or forged, thereby further preventing illegal access and enhancing the security of the virtualization environment.

[0051] Figure 1 The flowchart of the encryption and authentication method for the Linux virtual machine provided by the embodiment of the present invention is shown. Refer to Figure 1 The encryption and authentication method for the Linux virtual machine provided by the embodiment of the present invention includes:

[0052] S1, the virtual machine is powered on after being copied as a whole.

[0053] Specifically, the main functions of the vmware virtual machine (Linux) encryption and unique authentication are to ensure data security, access control, and non-replicability in the virtualization environment. By encrypting the virtual machine disk and the underlying storage, it can effectively prevent the leakage and tampering of data on the storage medium. Even if an attacker obtains access to the physical storage device, they cannot decrypt the sensitive data of the virtual machine, ensuring the non-replicability of the data. In addition, disk encryption ensures that even if the data is illegally copied or transferred, it cannot be effectively accessed. The unique authentication mechanism ensures that only authorized users can access the encrypted data through authentication, and the authentication process usually relies on unique authentication credentials, making the authentication information impossible to be copied or forged, thereby further preventing illegal access and enhancing the security of the virtualization environment.

[0054] S2, obtain the TPM authentication information, authenticate the TPM authentication information. If the authentication is successful, it is determined that the virtual machine is copied successfully, and the virtual machine power-on operation is executed.

[0055] As an optional implementation manner of the embodiment of the present invention, the obtaining the TPM authentication information and authenticating the TPM authentication information includes: obtaining the input TPM encryption key and verifying the TPM encryption key.

[0056] Specifically, TPM authentication, also known as Trusted Platform Module authentication, is a hardware-based security standard designed to provide a secure encryption processor for computer systems to store and manage encryption keys, passwords, and other sensitive information. TPM authentication ensures the credibility and security of computer systems, preventing unauthorized access and data leakage. The TPM module can generate and store encryption keys, perform encryption operations, and provide hardware-level security features. The main features of TPM authentication include:

[0057] 1) Key management: The TPM can generate and store encryption keys, which can be used to encrypt hard disk drives, protect network communications, etc.

[0058] 2) Platform authentication: The TPM can authenticate the identity of the computer, ensuring that only authorized devices can access specific networks or services.

[0059] 3) Integrity measurement: The TPM can record and verify the system startup process to ensure that the system has not been tampered with during startup.

[0060] 4) Secure storage: The TPM provides a secure storage area for storing sensitive data such as passwords and digital certificates.

[0061] After the Linux machine is manufactured, the system hardware + software will generate an encryption key for the entire machine through an encryption algorithm. This key needs to be decrypted by the TPM encryption key before the machine can be used normally. Therefore, when the virtual machine of the present invention is copied as a whole and powered on, it triggers the first authentication of the virtual machine, which is TPM authentication. If the key cannot be obtained, the virtual machine cannot be successfully started, and the services built on the virtual machine will not be available, which is equivalent to a copy failure. If the TPM encryption key is obtained through legal means or unconventional means and successfully verified, the system will boot normally.

[0062] S3. After the virtual machine is powered on, wait for the server to load.

[0063] Specifically, after the virtual machine of the present invention is powered on, it needs to complete the second authentication, that is, the control ledger password authentication, which can be automatically completed by the system in the present invention.

[0064] That is, after the virtual machine is powered on in step S2 and before the virtual machine is allowed to be used normally in step S5, the encryption and authentication method for the Linux virtual machine provided by the embodiments of the present invention further includes: authenticating the modified ssh password, and after the verification fails, preventing the operation of starting the virtual machine after it is copied as a whole. After the verification fails, by preventing the operation of starting the virtual machine after it is copied as a whole, the wab service cannot be started normally. As an optional implementation manner of the embodiments of the present invention, the authenticating the modified ssh password includes: obtaining the modified ssh password, obtaining the static key, verifying the static key, and after the verification passes, performing the operation of modifying the ssh password, and performing a hash judgment on the modified ssh password through the TPM encryption module.

[0065] Specifically, when the business of the present invention leaves the factory, it can default to provide the control ledger password and provide functions such as system power on and off, service restart, and network debugging, to help users debug the system under the console, so that the system business can maintain normal access.

[0066] This console method is completed by modifying the boot kernel of the coreos operating system. The detailed functions are as follows:

[0067] 1. Set the network IP, subnet mask, gateway, whether dhcp, etc. The system defaults to dhcp, and if dhcp fails, it can be manually specified through this operation.

[0068] 2. Service control. It is related to the specific filled business and provides a restart operation at the service level.

[0069] 3. Network Ping. When the specified IP or the IP changes, this option can be used to confirm the network connectivity.

[0070] 4. Modify the control ledger password. Users can modify the factory default control ledger password to ensure the security of the console.

[0071] 5. System control. Provide system power on, off, and restart functions. It is equivalent to executing the corresponding commands in the shell. The system recommends using this method to operate the system to facilitate the recovery of disk encryption and decryption.

[0072] 6. Create a secondary authentication method. This method is completed by the offline auth-2fa method. After configuring 2fa, when attempting to log in to the console, in addition to entering the account password, the user must also enter the 2fa key to complete the login, enhancing the security of the console.

[0073] It can be seen that the role of the second authentication of the present invention is disk decryption, which protects the code and data security of the service. Usually, users can normally use the system, but they cannot copy the code through the root user of ssh, so as to steal the core code through code reverse engineering technology. At this time, if the copier tries to reset the root password by modifying the Linux kernel, the present invention also verifies it, thus realizing security restrictions. Since the whole machine encrypts the disk, modifying the kernel changes the disk hash recorded by the TPM. When the modified kernel is booted, the hash comparison of the TPM fails, and the system will never be able to boot, and all services will be in a lost state. Even if the kernel boot is restored, the normal use of the service cannot be restored. Therefore, since the login password of ssh is reset by booting into the system kernel under Linux, modifying the login password of ssh changes the system resources, so the hash calculated by the TMP changes accordingly. Therefore, when the modification is completed and the system is restarted, the system hash judgment is inconsistent, and at this time, the Linux machine fails to start, and the service cannot be accessed either.

[0074] S4. Determine whether the IP is allocated. If the IP has been allocated, allow wab access.

[0075] As an optional implementation manner of the embodiment of the present invention, the method for encrypting and authenticating a Linux virtual machine provided by the embodiment of the present invention further includes: if the IP is not allocated, enter the boot Shell, manually allocate the IP, and perform the operation of allowing wab access.

[0076] S5. Verify the certificate information. If the verification passes, allow the virtual machine to be used normally.

[0077] Specifically, when the system completes the second authentication, the service can be used normally. When accessing the wab interface of the service, the third authentication of the virtual machine is triggered. This authentication is mainly a certificate authentication at the service granularity, and its main role is to protect the validity period and legality of the service. If the certificate expires or there is no valid certificate, the system will automatically redirect all URLs and trigger the authentication process. The authentication process mainly controls the generation of the unique id of the system through the hardware USB-Key to ensure the non-replicability of the system. There is a timing detection service in the virtual machine. Once the certificate becomes invalid, the system will always stay on the certificate authentication interface and cannot carry out business normally.

[0078] As an optional implementation manner of the embodiment of the present invention, the verification of the certificate information includes: determining whether there is a certificate; if there is the certificate, determine whether the certificate is valid through the USB-Key. If it is valid, determine that the verification passes. If it is invalid, prompt to upload a valid certificate; if there is no such certificate, prompt to upload a valid certificate.

[0079] Specifically, the present invention first determines whether there is a certificate; if the certificate exists, a legal certificate verification is performed. The verification method is as follows: Determine whether the certificate is valid through the USB-Key hardware. If it is valid, normal services can be accessed; if it is invalid, a prompt to re-upload a valid certificate is given. If the certificate does not exist, the function of prompting to upload a valid certificate is triggered. After uploading a valid certificate, continue to determine whether the certificate is valid through the USB-Key hardware. Only when the conditions are met: there is a certificate and the certificate is valid, will the authentication pass.

[0080] In summary, the present invention ensures the business security within the virtual machine at both the system level and the service level. The three authentication processes are not complex. Under normal circumstances, users will obtain the TPM key and authentication certificate, and can use it after inputting and uploading the certificate after the first boot. The second authentication is automatically decrypted by the system without user interaction, and only security prevention measures are taken from the perspective of preventing replication. In addition, the encryption and decryption processes during the normal use of the business by users are imperceptible.

[0081] It can be seen that through the encryption and authentication method of the Linux virtual machine provided by the embodiments of the present invention, a three-level security authentication system is established to ensure business security and non-replicability from the perspectives of software and hardware and business authentication; a security console can be built and operated and embedded in the operating system through a boot method; the security and uniqueness of the virtual machine and the non-replicability of the business system code under the supply mode of the vmware virtual machine are guaranteed.

[0082] Figure 3 The structural schematic diagram of the encryption and authentication device of the Linux virtual machine provided by the embodiments of the present invention is shown. This encryption and authentication device of the Linux virtual machine applies the above method. Only a simple description of the structure of the encryption and authentication device of the Linux virtual machine is given below. For other matters not covered, please refer to the relevant descriptions in the above encryption and authentication method of the Linux virtual machine. See Figure 3 The encryption and authentication device of the Linux virtual machine provided by the embodiments of the present invention includes:

[0083] A copy module, used to power on the virtual machine after it is copied as a whole;

[0084] A first authentication module, used to obtain TPM authentication information and authenticate the TPM authentication information;

[0085] A power-on module, used to determine that the virtual machine is copied successfully and execute the power-on operation of the virtual machine after the first authentication module authenticates successfully;

[0086] An access control module, used to determine whether an IP is allocated when waiting for the server to load after the virtual machine is powered on. If the IP has been allocated, wab access is allowed;

[0087] The second authentication module is used to verify the certificate information;

[0088] The processing module is used to allow the virtual machine to be used normally after the verification by the second authentication module;

[0089] The third authentication module is used to authenticate the modification of the ssh password after the virtual machine is powered on by the power-on module and before the processing module allows the virtual machine to be used normally. After the verification fails, the copy module is blocked from performing the operation of powering on the virtual machine after it is copied as a whole.

[0090] As an optional implementation manner of the embodiment of the present invention, the first authentication module obtains the TPM authentication information in the following manner and authenticates the TPM authentication information:

[0091] Obtain the input TPM encryption key and verify the TPM encryption key.

[0092] As an optional implementation manner of the embodiment of the present invention, the third authentication module authenticates the modification of the ssh password in the following manner:

[0093] Obtain the modified ssh password and obtain the static key, verify the static key, and after the verification passes, perform the operation of modifying the ssh password, and perform a hash judgment on the modified ssh password through the TPM encryption module.

[0094] As an optional implementation manner of the embodiment of the present invention, the second authentication module verifies the certificate information in the following manner:

[0095] Judge whether there is a certificate;

[0096] If there is the certificate, judge whether the certificate is valid through the USB-Key. If it is valid, determine that the verification passes. If it is invalid, prompt to upload a valid certificate;

[0097] If there is no such certificate, prompt to upload a valid certificate.

[0098] As an optional implementation manner of the embodiment of the present invention, the access control module is further used to, if the IP is not allocated, enter the boot Shell, manually allocate the IP, and perform the operation of accessing wab.

[0099] It can be seen that through the encryption and authentication device of the Linux virtual machine provided by the embodiment of the present invention, a three-time security authentication system is established to ensure the business security and non-replicability from the perspectives of software and hardware and business authentication; the security console can be built and operated and embedded in the operating system in a boot mode; the security and uniqueness of the virtual machine and the non-replicability of the business system code in the case of the vmware virtual machine supply mode are ensured.

[0100] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.

Claims

1. A Linux virtual machine encryption and authentication method, characterized in that: include: The virtual machine is booted after being copied as a whole; Acquire TPM authentication information, authenticate the TPM authentication information, and if the authentication is successful, determine that the virtual machine is successfully copied, and perform a startup operation on the virtual machine; After the virtual machine is powered on, wait for the server to load; Determine whether the IP is allocated. If the IP is allocated, wab access is allowed; Verifying the certificate information, and if the verification passes, allowing the virtual machine to be used normally; Wherein: after the virtual machine is powered on and before the virtual machine is allowed to be used normally, the process further includes: Authenticate the modification of the ssh password. If the authentication fails, prevent the virtual machine from being started after being copied as a whole.

2. The method according to claim 1, characterized in that The obtaining of TPM authentication information and authenticating the TPM authentication information includes: The input TPM encryption key is obtained, and the TPM encryption key is verified.

3. The method according to claim 2, characterized in that The authentication of modifying the ssh password comprises: Obtain the password for changing the ssh password, obtain the static key, verify the static key, and after the verification is passed, perform the operation of changing the ssh password, and perform hash judgment on the password for changing the ssh password through the TPM encryption module.

4. The method according to claim 3, characterized in that The verification of the certificate information includes: Determine whether a certificate exists; If the certificate exists, the USB-Key is used to determine whether the certificate is valid. If it is valid, the verification is confirmed to be successful. If it is invalid, a prompt is given to upload a valid certificate. If the certificate does not exist, you will be prompted to upload a valid certificate.

5. The method according to claim 4, characterized in that Also includes: If the IP is not assigned, enter the boot shell, manually assign the IP, and perform operations to allow wab access.

6. An encryption and authentication device for a Linux virtual machine, characterized in that: include: The copy module is used to start the virtual machine after it is copied as a whole; A first authentication module, used to obtain TPM authentication information and authenticate the TPM authentication information; A startup module, used to determine that the virtual machine is successfully copied and execute the startup operation of the virtual machine after the first authentication module succeeds in authentication; The access control module is used to determine whether the IP is allocated when the virtual machine is waiting for the server to load after it is powered on, and if the IP is allocated, allow wab access; The second authentication module is used to verify the certificate information; A processing module, configured to allow the virtual machine to be used normally after the second authentication module passes the verification; The third authentication module is used to authenticate the modification of the ssh password after the virtual machine is powered on by the power-on module and before the processing module allows the virtual machine to be used normally. If the verification fails, the copy module is prevented from executing the operation of powering on the virtual machine after being copied as a whole.

7. The device according to claim 6, characterized in that The first authentication module obtains TPM authentication information in the following manner and authenticates the TPM authentication information: The input TPM encryption key is obtained, and the TPM encryption key is verified.

8. The device according to claim 7, characterized in that The third authentication module authenticates the modification of the ssh password in the following manner: Obtain the password for changing the ssh password, obtain the static key, verify the static key, and after the verification is passed, perform the operation of changing the ssh password, and perform hash judgment on the password for changing the ssh password through the TPM encryption module.

9. The device according to claim 8, characterized in that The second authentication module verifies the certificate information in the following manner: Determine whether a certificate exists; If the certificate exists, the USB-Key is used to determine whether the certificate is valid. If it is valid, the verification is confirmed to be successful. If it is invalid, a prompt is given to upload a valid certificate. If the certificate does not exist, you will be prompted to upload a valid certificate.

10. The device according to claim 9, characterized in that The access control module is also used to enter the boot shell if the IP is not allocated, manually allocate the IP, and perform the operation of wab access.